Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 380

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Nearly half the stocks in the S&P 500 are at cross purposes with the rest of the market
Michael Burry believes the AI bubble 'may burst' sooner than he first believed
Anthropic launches cheaper AI model, its second release since CEO's call for a slowdown
Meta hires MongoDB CEO CJ Desai to lead enterprise unit. MongoDB shares crater
Treasury Secretary Scott Bessent hires Wall Street economist David Zervos
Snowpiercer: The Original Sinners Rewatch
Movie: Wrong Turn
Snowpiercer: A Beacon for Us All Rewatch
How promising does this article about Bezisterim sound?
Stock futures are little changed after higher yields lead to losing session: Live updates